Cybersecurity Principal Engineer
AmerisourceBergenAbout the role
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
What you will be doing
Summary:
This role is responsible for leading and overseeing the planning, execution, and management of complex multi-faceted projects related to risk management, mitigation and response, compliance, control assurance, and user awareness. Principal Engineers collaborate closely with other parts of the security team, customers, corporate IT, product, and engineering teams to design effective defense controls that limit threats and improve the company’s security posture. They develop and lead security strategies, initiatives, and policies/standards, ensuring the effectiveness of solutions, providing security-focused consultative services to the organization, and providing expertise and assistance to ensure the company’s infrastructure and information assets are protected. They provide subject matter expertise to the business and internal IT groups, , working closely with infrastructure engineers and leadership. They are expected to have a deep understanding of all and expertise in a few Information Security components. They play a key technical role in defining enterprise technology and Information Security principles and best practices. They act as a subject matter expert for Information Security and participate in senior leadership meetings to bring Information Security perspective to the company-wide IT Strategy.
Primary Duties and Responsibilities:
Lead Operational Excellence program to ensure Cybersecurity capabilities are optimized and meeting the needs of the Cybersecurity Response and Defense team
Analyzes trends, news and changes in threat and compliance environment with respect to organizational risk; advises organization management and develops and executes plans for compliance and mitigation of risk; oversees risk and compliance self-assessments and engages and coordinates third-party risk and compliance assessments
Oversees the response to information system security incidents, including investigation of, countermeasures to, and recovery from, computer-based attacks, unauthorized access, and policy breaches; engages, interacts and coordinates with third-party incident responders
Analyzes and recommends security controls and procedures in acquisition, development, and change management lifecycle of information systems, and provides oversight to ensure compliance.
Provides technical leadership of projects involving large-scale, complex and highly analytical tasks
Plans and leads upgrades to security measures and tools for the protections of information systems and networks
Formulates methodologies to monitor for as well as respond to security related events and assist in remediation efforts of cyber security incidents
Provides technical guidance to the network administrators and system administrators, monitors and maintains the current infrastructure, improves system performance, and automates system administration from security perspective
Provides technical guidance, coaching, and mentorship to other ISO Engineers in executing their tasks & responsibilities
Oversees the maintenance of service-level agreements (SLAs) to ensure that security controls are upheld
Leads implementation of enterprise-wide security policies, procedures, and standards across multiple platform and application environments to meet compliance responsibilities
Interfaces with business and IT leaders communicating security issues and responding to requests for assistance and information
Develops, refines, and implements security policies, procedures, and standards across multiple platforms and application environments to meet internal and external compliance responsibilities
Coordinates with other senior technical executives in testing, development, and other IT teams to design, develop and implement security systems that protect company physical and intangible assets effectively
Reviews technical/functional design documents, build, maintain and implement cybersecurity, data security, and cloud security solutions
Consults with other business and technical staff on potential business impacts of proposed changes to the security environment
Provides security briefings to advise on critical issues that may affect the enterprise
Analyzes and generates insights from the metrics and
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s